Back to skill

Security audit

NavClaw

Security checks for vulnerabilities and agentic risk

Overview

NavClaw is a real navigation helper, but it asks agents to reuse stored credentials and can automatically send detailed route logs to Mattermost without a strong per-run consent boundary.

Install only if you are comfortable with Amap receiving your route queries and, if Mattermost is configured, your route summaries and logs being posted to the configured channel. Prefer local-only use with --no-send, do not let the agent search general memory for secrets, store API keys in a proper secret manager or environment variables instead of config.py, and verify any Mattermost URL is HTTPS and trusted before enabling posting.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Warning
Location
wrapper.py:196
Finding

Route Messages and Sensitive Travel Logs Are Uploaded by Default

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
wrapper.py:52
Finding

Unvalidated Mattermost Base URL Can Expose Bot Credentials and Travel Data

Content
View full analysis
str: """上传文件到 Mattermost,返回 file_id""" try: with open(file_path, 'rb') as f: files = {'files': f} data = {'channel_id': MM_CHANNEL_ID} resp = requests.post( f"{MM_BASEURL}/api/v4/files", headers={"Authorization": f"Bearer {MM_BOT_TOKEN}"}, files=files, data=data, timeout=10 ) if resp.status_code == 201: result = resp.json() return result['file_infos'][0]['id'] else: print(f"⚠️ 文件上传失败: {resp.status_code} {resp.text[:200]}") return None except Exception as e: print(f"❌ 文件上传异常: {e}") return None ``` ```python def send_mattermost_message(text: str, file_ids: list = None) -> bool: """发送消息到 Mattermost""" try: payload = { "channel_id": MM_CHANNEL_ID, "message": text } if file_ids: payload["file_ids"] = file_ids resp = requests.post( f"{MM_BASEURL}/api/v4/posts", headers={ "Authorization": f"Bearer {MM_BOT_TOKEN}", "Content-Type": "application/json" }, json=payload, timeout=10 ) if resp.status_code == 201: return True else: print(f"⚠️ 消息发送失败: {resp.status_code} {resp.text[:200]}") return False except Exception as e: print(f"❌ 消息发送异常: {e}") return False ``` ### Technical Analysis `MM_BASEURL` is read from configuration and concatenated directly into request URLs. The code does not enforce HTTPS, vali ...[truncated 1585 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL_EN.md:22
Finding

Skill Instructions Direct the Agent to Search General Memory for Credentials

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Third-Party Dependency Is Not Reproducibly Pinned

Content
View full analysis
=2.20.0 ``` ### Technical Analysis The dependency specification accepts every `requests` release from version 2.20.0 onward, including future versions that were not reviewed with this project. No lockfile or package hash is supplied. Consequently, two installations at different times can resolve to different artifacts, reducing build reproducibility and increasing exposure to future upstream compromise or incompatible releases. The package name is legitimate, and the audit found no evidence of dependency confusion, typosquatting, or a currently malicious package. This is a preventive supply-chain hardening issue rather than evidence of active exploitation. ### Attack Path 1. A user or deployment system installs dependencies with `pip install -r requirements.txt`. 2. The resolver selects the latest package version satisfying `requests>=2.20.0`. 3. A future compromised, unexpectedly changed, or incompatible release is downloaded from the configured package index. 4. The package executes during import or affects the Skill's outbound HTTP processing. ### Impact Assessment A compromised dependency executes with the same privileges as the Python process running the Skill. This could theoretically expose the Amap key, Mattermost token, route data, accessible files, and network access available to that process. Actual impact depends on the runtime account and environment. No present compromise was identified. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (48)

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README explicitly instructs the agent to search memory for an existing API key and reuse it before asking the user. This encourages cross-context secret retrieval and reuse, which can cause an agent to access stored credentials beyond the user's immediate, explicit consent and increases the risk of secret exfiltration or misuse.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The installation prompt directs the agent to look for Mattermost connection secrets in memory or configuration and use them if found. This is dangerous because it trains the agent to discover and operationalize stored tokens automatically, which weakens least-privilege boundaries and can enable unauthorized messaging or token abuse.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · README_EN.md (reported line 7)May include surrounding context.

md
[![Python 3.8+](https://img.shields.io/badge/Python-3.8+-green.svg)](https://www.python.org/)
[![ClawHub](https://img.shields.io/badge/ClawHub-navclaw-orange)](https://clawhub.ai/AI4MSE/navclaw)

**Intelligent route planner** — standalone or powered by OpenClaw. Congestion avoidance, exhaustive route optimization, iOS & Android deep links that open your navigation app in one tap.Bonus toolbox like weather, POI search, geocoding, district query, etc.(note Bonus toolbox setup needs to update SKILL_EN.md, see github project for details) Currently supports Amap, more platforms coming

First supported navigation platform: **Amap** · More coming soon

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The stated purpose is navigation, but the skill also instructs sending results and log files to Mattermost and handling external chat credentials. This materially expands the data-flow surface beyond navigation and can cause user locations, route details, and logs to be transmitted to third-party systems without a clear, upfront declaration.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This line asks the agent to obtain Mattermost bot credentials from memory, config, or the user and write them into config.py. Bot tokens can grant posting or file-upload rights to organizational chat systems, so harvesting and persisting them creates significant risk of unauthorized messaging, data leakage, and credential compromise.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README advertises a natural-language trigger that is broad enough to encourage automatic execution from ordinary conversation. In an agent setting, ambiguous trigger phrases can cause unintended invocation from user messages or forwarded content, leading the agent to run tools without a strong confirmation boundary.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
74% confidence
Finding

The README recommends updating long-term memory or creating a skill so the behavior persists and can be triggered later. In combination with broad natural-language activation and secret-handling guidance, this persistence makes the skill more dangerous because risky behavior and credential reuse rules survive beyond the initial installation context.

Content

Scanner excerpt · README.md (reported line 46)May include surrounding context.

md
3. 复制 `config_example.py` → `config.py`,填入 Amap API Key
   Copy `config_example.py` → `config.py`, fill in your Amap API key
4. 更新 OpenClaw 的长期记忆或制作技能
   Update OpenClaw's long-term memory or create a skill
5. 直接说 / Just say: *"从北京南站到广州南站导航"*

### 独立使用 / Standalone

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The long-term memory template defines an auto-execution trigger for phrases like navigating from one place to another, but does not impose clear constraints or a confirmation gate. Persisting this behavior in memory increases the chance of accidental or prompt-injected tool execution across future sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instructions tell the agent to place the user's Amap API key into config.py, but do not warn about the security implications of storing credentials in a local file. In agent environments, this can normalize insecure secret handling and make later leakage via logs, memory, backups, or workspace access more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README advertises Mattermost integration and automatic sending of navigation results without clearly warning that route details, destinations, and potentially sensitive travel patterns may be transmitted to an external server. In a navigation context, origin/destination data can reveal highly sensitive personal information such as home, work, or travel habits.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README_EN.md (reported line 30)May include surrounding context.

md
1. Clone NavClaw into your OpenClaw project directory, or place it anywhere on your OpenClaw server
2. Copy `config_example.py` → `config.py`, fill in your Amap API key
3. Update OpenClaw's long-term memory or create a skill
4. Just say: *"Navigate from Beijing South Station to Guangzhou South Station"*

### Standalone

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly tells the agent/user to write an Amap API key into config.py, which is described as a local file-based configuration. Storing secrets in plaintext increases the risk of accidental disclosure through local file access, backups, logs, screenshots, or later commits, especially in an agent workflow that may edit files automatically.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares no explicit tool scope even though its documented behavior includes file writes and outbound network access. Without clear permission boundaries, an agent or reviewer cannot reliably understand or constrain what the skill is allowed to do, increasing the chance of unintended data writes or data exfiltration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill asks for origin/destination and an Amap API key, but does not clearly warn users that location data will be sent to external routing services. Location information is sensitive, and users need informed consent before their travel requests are transmitted off-platform.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly tells the agent to search memory for a previously provided Amap API key and reuse it in configuration. Reusing secrets from memory without fresh, context-specific consent violates least-privilege principles and risks unauthorized credential use or unintended disclosure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrase "drive to [destination]" is broad enough to match ordinary conversation, making accidental invocation more likely. In this skill, accidental invocation is more dangerous because execution may perform external API calls, use stored credentials, and share outputs to other platforms.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow and backup instructions describe posting route results and log attachments to Mattermost or reading log contents back into chat, but the description lacks a clear warning that this sharing occurs. Logs can contain sensitive route details, timestamps, identifiers, or debugging data, so undisclosed reposting significantly increases privacy and data leakage risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The fallback behavior tells the agent to read log contents and send them to the user if attachments are not possible. Logs frequently contain more information than intended for end users, including request parameters, file paths, tokens, errors, and route history, so copying them into chat increases the chance of sensitive data exposure.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The setup instructions tell the agent to ask for Mattermost bot credentials if missing and write them into config.py. Having an agent collect and persist chat-platform credentials in a general configuration file creates significant secret-handling risk, including accidental exposure through files, logs, version control, or later message forwarding.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs the agent to retrieve an Amap API key from memory and later persist credentials into config.py. Asking an agent to mine prior context or stored memory for secrets and write them to disk expands the skill from navigation into credential handling, creating risk of unauthorized secret reuse, accidental disclosure, and long-term persistence of sensitive data.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Directing the agent to retrieve credentials from memory/config or prompt for them creates a secret-access workflow inside a navigation skill. That is dangerous because the agent may access previously stored secrets outside the current task scope and persist them in less secure locations.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL_EN.md (reported line 46)May include surrounding context.

md
**Workflow**:

Calls `wrapper.py --origin "origin" --dest "destination"`, goes through a five-stage planning process (Wide Search → Fine Filter → Deep Processing → Iterative Optimization → Route Finalization), generates a large number of route options (including detour optimizations), and automatically sends 3 messages to the chat platform + log attachment:

- Message 1 — full comparison table
- Message 2 — quick navigation links

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL_EN.md (reported line 58)May include surrounding context.

md
**Workflow**:

Calls `wrapper.py --origin "origin" --dest "destination"`, goes through a five-stage planning process (Wide Search → Fine Filter → Deep Processing → Iterative Optimization → Route Finalization), generates a large number of route options (including detour optimizations), and automatically sends 3 messages to the chat platform + log attachment:

- Message 1 — full comparison table
- Message 2 — quick navigation links

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill describes sending route information and logs to Mattermost or other chat tools, but it does not warn that logs may contain sensitive location data, tokens, or debugging details. Route origins, destinations, and attached logs can reveal personal travel patterns or operational information if forwarded broadly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill adds Mattermost bot posting and direct file-upload behavior that is not necessary for core route computation. That broadens the capability surface to external messaging APIs, increasing the chance of unintended data exfiltration, spam, or misuse of bot credentials if the agent is induced to post sensitive content or logs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.